Ostorlab outperforms Mythos, Microsoft, and Wiz. Our CyberGym benchmark results, at a fraction of the cost. Learn more

Sohaib Harraoui

Security Engineer LinkedIn

Sohaib Harraoui is a Security Engineer at Ostorlab, where he focuses on application security, attack surface discovery, and offensive vulnerability research. With a background in software engineering and systems, he investigates web and mobile ecosystems, analyzes how software assumptions break, and develops reproducible proof-of-concept exploits. His writing helps engineering and security teams understand real-world attack vectors, evaluate emerging threats, and build more resilient systems.

Articles by Sohaib Harraoui

Learn how B2B SaaS startups bypass the 4-week consultancy delay to generate audit-ready SOC 2 pentest reports and Letters of Attestation in 24–48 hours.

Security

Ostorlab Neutron Leads UC Berkeley CyberGym: 100% Detection and 96.75% Verified Exploitation

A technical deep-dive into how Ostorlab Neutron achieved 100% vulnerability detection and a 96.75...

Tue 15 September 2026

Security

Autonomous Pentesting vs. Traditional Penetration Testing: Where Agentic AI Delivers—and Where Humans Still Lead

Compare traditional pentesting, PTaaS, and autonomous agentic AI testing: discover where autonomo...

Tue 08 September 2026

Security

Breaking Down the Latest Version of GoPhish: Source-Code Assessment with Ostorlab Agentic Deep Scan

A technical assessment of the latest version of GoPhish that examines how the platform handles tr...

Thu 16 July 2026

A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteLLM Proxy API. Improper parameterization of the Bearer token within raw SQL queries used for complex multi-table joins allows blind boolean-based timing attacks, enabling unauthenticated attackers to exfiltrate sensitive data including virtual API keys, user information, and LLM spend logs directly from the database.